• DocumentCode
    3452489
  • Title

    Beyond proof-of-compliance: safety and availability analysis in trust management

  • Author

    Li, Ninghui ; Winsborough, William H.

  • Author_Institution
    Dept. of Comput. Sci., Stanford Univ., CA, USA
  • fYear
    2003
  • fDate
    11-14 May 2003
  • Firstpage
    123
  • Lastpage
    139
  • Abstract
    Trust management is a form of distributed access control using distributed policy. statements. Since one party may delegate partial control to another party, it is natural to ask what permissions may be granted as the result of policy changes by other parties. We study security properties such as safety, and availability for a family of trust management languages, devising algorithms for deciding the possible consequences of certain changes in policy. While trust management is more powerful in certain ways than mechanisms in the access matrix model, and the security properties considered are more than simple safety, we find that in contrast to the classical HRU undecidability of safety properties, our primary security properties are decidable. In particular, most properties we studied are decidable in polynomial time. Containment, the most complicated security property we studied, is decidable in polynomial time for the simplest TM language in the family. The problem becomes co-NP-hard when intersection or linked roles are added to the language.
  • Keywords
    authorisation; computational complexity; decidability; TM language; availability analysis; co-NP-hard problem; containment; distributed access control; distributed policy statements; intersection; linked roles; polynomial time; proof-of-compliance; safety; security properties; security properties decidability; trust management languages; Access control; Availability; Computer network management; Computer science; Intelligent networks; Laboratories; Mechanical factors; Polynomials; Safety; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2003. Proceedings. 2003 Symposium on
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-1940-7
  • Type

    conf

  • DOI
    10.1109/SECPRI.2003.1199332
  • Filename
    1199332